// Ubuntu 192.168.2.201
root@Ubuntu-Asus 192.168.2.201 15:17:27 ~
tshark: Lua: Error during loading:
 [string "/usr/share/wireshark/init.lua"]:46: dofile has been disabled due to running Wireshark as superuser. See http://wiki.wireshark.org/CaptureSetup/CapturePrivileges for help in running Wireshark as an unprivileged user.
Running as user "root" and group "root". This could be dangerous.
Capturing on 'docker0'
  1   0.000000 02:42:ac:11:00:02 -> Broadcast    ARP 42 Who has 172.17.0.1?  Tell 172.17.0.2
  2   0.000033 02:42:08:03:7a:e6 -> 02:42:ac:11:00:02 ARP 42 172.17.0.1 is at 02:42:08:03:7a:e6
  3   0.000046   172.17.0.2 -> 172.18.0.2   TCP 74 59523 > mysql [SYN] Seq=0 Win=29200 Len=0 MSS=1460 SACK_PERM=1 TSval=39321424 TSecr=0 WS=128
  4   0.032752   172.18.0.2 -> 172.17.0.2   TCP 74 mysql > 59523 [SYN, ACK] Seq=0 Ack=1 Win=28960 Len=0 MSS=1460 SACK_PERM=1 TSval=182278505 TSecr=39321424 WS=128
  5   0.032982   172.17.0.2 -> 172.18.0.2   TCP 66 59523 > mysql [ACK] Seq=1 Ack=1 Win=29312 Len=0 TSval=39321432 TSecr=182278505
  6   0.057003   172.18.0.2 -> 172.17.0.2   MySQL 144 Server Greeting proto=10 version=5.7.10
  7   0.057052   172.17.0.2 -> 172.18.0.2   TCP 66 59523 > mysql [ACK] Seq=1 Ack=79 Win=29312 Len=0 TSval=39321438 TSecr=182278536
  8   0.057149   172.17.0.2 -> 172.18.0.2   MySQL 249 Login Request user=root
  9   0.091636   172.18.0.2 -> 172.17.0.2   TCP 66 mysql > 59523 [ACK] Seq=79 Ack=184 Win=30080 Len=0 TSval=182278571 TSecr=39321438
 10   0.097889   172.18.0.2 -> 172.17.0.2   MySQL 77 Response OK
 11   0.098129   172.17.0.2 -> 172.18.0.2   MySQL 103 Request Query
 12   0.125942   172.18.0.2 -> 172.17.0.2   MySQL 158 Response
 13   0.162720   172.17.0.2 -> 172.18.0.2   TCP 66 59523 > mysql [ACK] Seq=221 Ack=182 Win=29312 Len=0 TSval=39321465 TSecr=182278599
13  14   4.602119   172.17.0.2 -> 172.18.0.2   MySQL 71 Request Quit
 15   4.602301   172.17.0.2 -> 172.18.0.2   TCP 66 59523 > mysql [FIN, ACK] Seq=226 Ack=182 Win=29312 Len=0 TSval=39322574 TSecr=182278599
 16   4.670611   172.17.0.2 -> 172.18.0.2   TCP 66 [TCP Retransmission] 59523 > mysql [FIN, ACK] Seq=226 Ack=182 Win=29312 Len=0 TSval=39322592 TSecr=182278599
 17   4.675746   172.18.0.2 -> 172.17.0.2   TCP 66 [TCP Previous segment not captured] mysql > 59523 [ACK] Seq=183 Ack=227 Win=30080 Len=0 TSval=182283170 TSecr=39322592
 18   4.843638   172.18.0.2 -> 172.17.0.2   TCP 66 [TCP Retransmission] mysql > 59523 [FIN, ACK] Seq=182 Ack=227 Win=30080 Len=0 TSval=182283338 TSecr=39322592
 19   4.843713   172.17.0.2 -> 172.18.0.2   TCP 66 59523 > mysql [ACK] Seq=227 Ack=183 Win=29312 Len=0 TSval=39322635 TSecr=182283338
19  20   5.038625 02:42:08:03:7a:e6 -> 02:42:ac:11:00:02 ARP 42 Who has 172.17.0.2?  Tell 172.17.0.1
 21   5.038670 02:42:ac:11:00:02 -> 02:42:08:03:7a:e6 ARP 42 172.17.0.2 is at 02:42:ac:11:00:02
21 ^C
$ tshark -i wlan0 | grep mysql
tshark: Lua: Error during loading:
 [string "/usr/share/wireshark/init.lua"]:46: dofile has been disabled due to running Wireshark as superuser. See http://wiki.wireshark.org/CaptureSetup/CapturePrivileges for help in running Wireshark as an unprivileged user.
Running as user "root" and group "root". This could be dangerous.
Capturing on 'wlan0'
405 396  64.586967 192.168.2.201 -> 172.18.0.2   TCP 74 59523 > mysql [SYN] Seq=0 Win=29200 Len=0 MSS=1460 SACK_PERM=1 TSval=39321424 TSecr=0 WS=128
397  64.619458   172.18.0.2 -> 192.168.2.201 TCP 74 mysql > 59523 [SYN, ACK] Seq=0 Ack=1 Win=28960 Len=0 MSS=1460 SACK_PERM=1 TSval=182278505 TSecr=39321424 WS=128
418 398  64.619905 192.168.2.201 -> 172.18.0.2   TCP 66 59523 > mysql [ACK] Seq=1 Ack=1 Win=29312 Len=0 TSval=39321432 TSecr=182278505
400  64.643935 192.168.2.201 -> 172.18.0.2   TCP 66 59523 > mysql [ACK] Seq=1 Ack=79 Win=29312 Len=0 TSval=39321438 TSecr=182278536
402  64.678468   172.18.0.2 -> 192.168.2.201 TCP 66 mysql > 59523 [ACK] Seq=79 Ack=184 Win=30080 Len=0 TSval=182278571 TSecr=39321438
406  64.749772 192.168.2.201 -> 172.18.0.2   TCP 66 59523 > mysql [ACK] Seq=221 Ack=182 Win=29312 Len=0 TSval=39321465 TSecr=182278599
466 444  69.189204 192.168.2.201 -> 172.18.0.2   TCP 66 59523 > mysql [FIN, ACK] Seq=226 Ack=182 Win=29312 Len=0 TSval=39322574 TSecr=182278599
446  69.257519 192.168.2.201 -> 172.18.0.2   TCP 66 [TCP Retransmission] 59523 > mysql [FIN, ACK] Seq=226 Ack=182 Win=29312 Len=0 TSval=39322592 TSecr=182278599
471 447  69.262593   172.18.0.2 -> 192.168.2.201 TCP 66 [TCP Previous segment not captured] mysql > 59523 [ACK] Seq=183 Ack=227 Win=30080 Len=0 TSval=182283170 TSecr=39322592
448  69.430439   172.18.0.2 -> 192.168.2.201 TCP 66 [TCP Retransmission] mysql > 59523 [FIN, ACK] Seq=182 Ack=227 Win=30080 Len=0 TSval=182283338 TSecr=39322592
449  69.430616 192.168.2.201 -> 172.18.0.2   TCP 66 59523 > mysql [ACK] Seq=227 Ack=183 Win=29312 Len=0 TSval=39322635 TSecr=182283338
613 ^C
// Centos 192.168.2.202
[root@Centos-L410 docker]
Running as user "root" and group "root". This could be dangerous.
Capturing on 'docker0'
  1 0.000000000 192.168.2.201 -> 172.18.0.2   TCP 74 59523 > mysql [SYN] Seq=0 Win=29200 Len=0 MSS=1460 SACK_PERM=1 TSval=39321424 TSecr=0 WS=128
  2 0.000094913   172.18.0.2 -> 192.168.2.201 TCP 74 mysql > 59523 [SYN, ACK] Seq=0 Ack=1 Win=28960 Len=0 MSS=1460 SACK_PERM=1 TSval=182278505 TSecr=39321424 WS=128
  3 0.030116575 192.168.2.201 -> 172.18.0.2   TCP 66 59523 > mysql [ACK] Seq=1 Ack=1 Win=29312 Len=0 TSval=39321432 TSecr=182278505
  4 0.030976025   172.18.0.2 -> 192.168.2.201 MySQL 144 Server Greeting proto=10 version=5.7.10
  5 0.056176778 192.168.2.201 -> 172.18.0.2   TCP 66 59523 > mysql [ACK] Seq=1 Ack=79 Win=29312 Len=0 TSval=39321438 TSecr=182278536
  6 0.066130572 192.168.2.201 -> 172.18.0.2   MySQL 249 Login Request user=root
  7 0.066173733   172.18.0.2 -> 192.168.2.201 TCP 66 mysql > 59523 [ACK] Seq=79 Ack=184 Win=30080 Len=0 TSval=182278571 TSecr=39321438
  8 0.066262220   172.18.0.2 -> 192.168.2.201 MySQL 77 Response OK
  9 0.093104979 192.168.2.201 -> 172.18.0.2   MySQL 103 Request Query
 10 0.093395793   172.18.0.2 -> 192.168.2.201 MySQL 158 Response
 11 0.159316774 192.168.2.201 -> 172.18.0.2   TCP 66 59523 > mysql [ACK] Seq=221 Ack=182 Win=29312 Len=0 TSval=39321465 TSecr=182278599
 12 4.599128670 192.168.2.201 -> 172.18.0.2   MySQL 71 Request Quit
 13 4.599292166   172.18.0.2 -> 192.168.2.201 TCP 66 mysql > 59523 [FIN, ACK] Seq=182 Ack=226 Win=30080 Len=0 TSval=182283104 TSecr=39322574
 14 4.665013615 192.168.2.201 -> 172.18.0.2   TCP 66 59523 > mysql [FIN, ACK] Seq=226 Ack=182 Win=29312 Len=0 TSval=39322592 TSecr=182278599
 15 4.665053144   172.18.0.2 -> 192.168.2.201 TCP 66 mysql > 59523 [ACK] Seq=183 Ack=227 Win=30080 Len=0 TSval=182283170 TSecr=39322592
 16 4.832475608   172.18.0.2 -> 192.168.2.201 TCP 66 [TCP Retransmission] mysql > 59523 [FIN, ACK] Seq=182 Ack=227 Win=30080 Len=0 TSval=182283338 TSecr=39322592
 17 4.849718662 192.168.2.201 -> 172.18.0.2   TCP 66 59523 > mysql [ACK] Seq=227 Ack=183 Win=29312 Len=0 TSval=39322635 TSecr=182283338
 18 5.014473661 02:42:38:14:f7:88 -> 02:42:ac:12:00:02 ARP 42 Who has 172.18.0.2?  Tell 172.18.0.1
 19 5.014525272 02:42:ac:12:00:02 -> 02:42:38:14:f7:88 ARP 42 172.18.0.2 is at 02:42:ac:12:00:02
^C19 packets captured
[root@Centos-L410 arnes]
Running as user "root" and group "root". This could be dangerous.
Capturing on 'wlp5s0'
354 318 39.616348312 192.168.2.201 -> 172.18.0.2   TCP 74 59523 > mysql [SYN] Seq=0 Win=29200 Len=0 MSS=1460 SACK_PERM=1 TSval=39321424 TSecr=0 WS=128
319 39.616526473   172.18.0.2 -> 192.168.2.201 TCP 74 mysql > 59523 [SYN, ACK] Seq=0 Ack=1 Win=28960 Len=0 MSS=1460 SACK_PERM=1 TSval=182278505 TSecr=39321424 WS=128
321 39.646494918 192.168.2.201 -> 172.18.0.2   TCP 66 59523 > mysql [ACK] Seq=1 Ack=1 Win=29312 Len=0 TSval=39321432 TSecr=182278505
324 39.672552747 192.168.2.201 -> 172.18.0.2   TCP 66 59523 > mysql [ACK] Seq=1 Ack=79 Win=29312 Len=0 TSval=39321438 TSecr=182278536
326 39.682593002   172.18.0.2 -> 192.168.2.201 TCP 66 mysql > 59523 [ACK] Seq=79 Ack=184 Win=30080 Len=0 TSval=182278571 TSecr=39321438
333 39.775693441 192.168.2.201 -> 172.18.0.2   TCP 66 59523 > mysql [ACK] Seq=221 Ack=182 Win=29312 Len=0 TSval=39321465 TSecr=182278599
379 384 44.215727358   172.18.0.2 -> 192.168.2.201 TCP 66 mysql > 59523 [FIN, ACK] Seq=182 Ack=226 Win=30080 Len=0 TSval=182283104 TSecr=39322574
386 44.281387627 192.168.2.201 -> 172.18.0.2   TCP 66 59523 > mysql [FIN, ACK] Seq=226 Ack=182 Win=29312 Len=0 TSval=39322592 TSecr=182278599
387 44.281474299   172.18.0.2 -> 192.168.2.201 TCP 66 mysql > 59523 [ACK] Seq=183 Ack=227 Win=30080 Len=0 TSval=182283170 TSecr=39322592
421 389 44.448924489   172.18.0.2 -> 192.168.2.201 TCP 66 [TCP Retransmission] mysql > 59523 [FIN, ACK] Seq=182 Ack=227 Win=30080 Len=0 TSval=182283338 TSecr=39322592
391 44.466095818 192.168.2.201 -> 172.18.0.2   TCP 66 59523 > mysql [ACK] Seq=227 Ack=183 Win=29312 Len=0 TSval=39322635 TSecr=182283338
596 ^C
1 packet dropped